Enterasys Networks 9034385 Plumbing Product User Manual


 
Summary
Enterasys NAC Design Guide 3-13
5.Remediation‐Whenthequarantinedenduseropensawebbrowsertoanywebsite,itstrafficis
dynamicallyredirectedtoaRemediationwebpagethatdescribesthecomplianceviolationsand
providesremediationsstepsfortheusertoexecuteinordertoachievecompliance.Aftertaking
theappropriateremediationsteps,the
enduserclicksonabuttononthewebpagetoreattempt
networkaccess,forcingthereassessmentoftheendsystem.Atthispoint,theEnterasysNAC
solutiontransitionstheendsystemthroughtheentireNACcycle,reassessingthesecurity
postureoftheendsystemtodetermineif
theremediationtechniques weresuccessfullyfollowed.
Iftheendsystemisnowcompliantwithnetworksecuritypolicy,theNACControllerauthorizes
theendsystemwiththeappropriateaccesspolicy.Iftheendsystemisnotcompliant,theend
systemisrestrictedaccesstothenetworkbyassigningapolicytothe
endsystemontheNAC
Controller,andtheprocessstartsagain.
Summary
Thedecisionwhethertodeployinlineoroutofbandnetworkaccesscontroldependsonthe
infrastructuredevicesdeployedinyournetwork.Forsomenetworktopologies,inlineNAC
utilizingthe NACControllerappliancemayberequiredwhileforothernetworkconfigurations,
outofbandNACutilizingtheNACGatewayappliancemay
beused.
ThefollowingtablesummarizesfourNACusescenariosandtheirNACappliancerequirements.
TheEnterasysNACsolutioniscapableofimplementingnetworkaccesscontrolforallfouruse
scenariosaswellasenvironmentswithmixedusescenariosthatmayrequiretheconcurrent
deploymentofinlineandoutofband
NAC.
.
Table 3-1 Use Scenario Summaries
Use Scenario Summary and Appliance Requirements
Scenario 1:
Intelligent wired access
edge
Summary:
Intelligent edge switches in the network access layer provide authentication and
authorization for connecting end-systems.
Appliance Requirement: NAC Gateway
The NAC Gateway appliance provides out-of-band network access control by
leveraging the intelligent edge switches as the authorization point for connecting
end-systems.
Scenario 2:
Intelligent wireless
access edge
Summary:
Thick Access Points (APs), or wireless switches with thin APs, provide
authentication and authorization for connecting end-systems.
Appliance Requirement: NAC Gateway
The NAC Gateway appliance provides out-of-band network access control by
leveraging the intelligent wireless infrastructure devices as the authorization
point for connecting end-systems.
Scenario 3:
Non-intelligent access
edge (wired and
wireless)
Summary:
Non-intelligent edge switches in the network access layer are not capable of
providing authentication and authorization for connecting end-systems.
Appliance Requirement: NAC Controller
Inline network access control is implemented by positioning the NAC Controller
appliance at a strategic point in the network topology as the authorization point
for end-system traffic.